Title: Introduced protections against user-controlled internal request forwarding by pixeebot[bot] · Pull Request #29 · Pixee-Bot-Java/flow · GitHub
Open Graph Title: Introduced protections against user-controlled internal request forwarding by pixeebot[bot] · Pull Request #29 · Pixee-Bot-Java/flow
X Title: Introduced protections against user-controlled internal request forwarding by pixeebot[bot] · Pull Request #29 · Pixee-Bot-Java/flow
Description: Vaadin Flow is a Java framework binding Vaadin web components to Java. This is part of Vaadin 10+. - Introduced protections against user-controlled internal request forwarding by pixeebot[bot] · Pull Request #29 · Pixee-Bot-Java/flow
Open Graph Description: This change hardens all ServletRequest#getRequestDispatcher(String) calls against attack. There is a built-in HTTP method for sending clients to another resource: the client-side redirect. However,...
X Description: This change hardens all ServletRequest#getRequestDispatcher(String) calls against attack. There is a built-in HTTP method for sending clients to another resource: the client-side redirect. However,...
Opengraph URL: https://github.com/Pixee-Bot-Java/flow/pull/29
X: @github
Domain: patch-diff.githubusercontent.com
| route-pattern | /_view_fragments/voltron/pull_requests/show/:user_id/:repository/:id/pull_request_layout(.:format) |
| route-controller | voltron_pull_requests_fragments |
| route-action | pull_request_layout |
| fetch-nonce | v2:8c145a05-f977-b43e-a6cc-8a39dd437ca9 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | CD24:D536F:103EFCD:14E8478:698FD2F7 |
| html-safe-nonce | 3fe17e0ea6ece732d1286920eaf70a558f4b89c70d44ab5e4f1ff58f44de8963 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDRDI0OkQ1MzZGOjEwM0VGQ0Q6MTRFODQ3ODo2OThGRDJGNyIsInZpc2l0b3JfaWQiOiI3OTE5NzAxODcwNzkzMDgwMjMiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | d69600a5c1a9265acc77a022b37237c459f646406c03c426a769948f450ddf9c |
| hovercard-subject-tag | pull_request:2542887854 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/voltron/pull_requests/show/Pixee-Bot-Java/flow/29/pull_request_layout |
| twitter:image | https://opengraph.githubassets.com/5ae56f9d7f489b1d8ecbe400f2740afb3924bc5f6d067372d7dc68b04f5a2bb5/Pixee-Bot-Java/flow/pull/29 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/5ae56f9d7f489b1d8ecbe400f2740afb3924bc5f6d067372d7dc68b04f5a2bb5/Pixee-Bot-Java/flow/pull/29 |
| og:image:alt | This change hardens all ServletRequest#getRequestDispatcher(String) calls against attack. There is a built-in HTTP method for sending clients to another resource: the client-side redirect. However,... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | pixeebot[bot] |
| hostname | github.com |
| expected-hostname | github.com |
| None | 42c603b9d642c4a9065a51770f75e5e27132fef0e858607f5c9cb7e422831a7b |
| turbo-cache-control | no-cache |
| go-import | github.com/Pixee-Bot-Java/flow git https://github.com/Pixee-Bot-Java/flow.git |
| octolytics-dimension-user_id | 143516492 |
| octolytics-dimension-user_login | Pixee-Bot-Java |
| octolytics-dimension-repository_id | 795756272 |
| octolytics-dimension-repository_nwo | Pixee-Bot-Java/flow |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | true |
| octolytics-dimension-repository_parent_id | 34809191 |
| octolytics-dimension-repository_parent_nwo | vaadin/flow |
| octolytics-dimension-repository_network_root_id | 34809191 |
| octolytics-dimension-repository_network_root_nwo | vaadin/flow |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | d320682233dfd4d28c0b30554a564c2fcd229032 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width